Secure a till device

Enrol a tablet or PC so every offline item it sends is signed, and deal with quarantined or revoked devices.

Required permission: pos.sync.manage

Before you begin

  • You have pos.sync.manage.
  • You are on the device that will be used as the till, and the register exists.
  • The register has no active device yet. A register can have only one active device key.

Why secure a device

An offline till stores bills and sends them later. Securing the device gives it a signing key so the system can tell a bill really came from that till and that nobody changed it on the way.

Steps: secure the device

  1. Open Point of Sale > Point of sale > Launch POS.
  2. On the register's card, press Secure this device.
  3. Wait for the confirmation.

What happens next

  • The browser makes a key pair. The private key stays on the device; the public key is enrolled for the register.
  • The register is marked require signed sync.
  • From now on every queued item is signed and carries a sequence number (1, 2, 3...). The system remembers the last sequence it accepted.
  • An unsigned browser can no longer open the register or sync for it: 'This register requires an enrolled signed device.'
  • The device is listed under Point of Sale > POS setup > Devices and Hardware > Device monitor, state active.

What the system protects against

AttemptResult
Resend the same item exactlyTreated as a duplicate; nothing happens twice
Same sequence or same identifier with different contentItem is quarantined with a conflict id; the original sale is unchanged
Sequence lower than the last acceptedQuarantined as a sequence rollback
Wrong signature'The offline item signature is not valid.'
Content does not match the signed hash'The signed payload hash does not match the item.'
Device used for another register'This device is not bound to that register.'
Revoked device'This device credential has been revoked.'

Quarantined items are listed as sync conflicts with their reason (sequence reuse, identifier reuse or sequence rollback). They need a supervisor's review. They are not posted.

Replace or revoke a device

Revoking a lost or replaced device is not available on a screen yet; your administrator does it through the system's integration interface. After revoking:

  • The device's state is revoked and new uploads from it are refused.
  • Its earlier bills and conflicts stay.
  • Revoking again does nothing.
  • The register stays signed-only, so enrol the replacement device before trading.

A device whose key you want to change must be revoked first: 'Revoke the active device before changing its key or register.' Enrolling the same key on the same register again does nothing.

Enrolment rules

SituationMessage
No register chosen'Choose the register this device belongs to.'
No device identifier'Give the device a stable identifier.'
Bad key'The Ed25519 public key is not valid.'

Good to know

  • Securing is per register and per device. Tablets used on different registers are secured separately.
  • Do not clear the browser's site data on a secured till: the key lives there. If it is lost, revoke the device and enrol again.
  • Securing the device is the safeguard against forged uploads. It does not replace cashier sign-in.
  • The queue and conflicts are visible under Synchronisation (Monitor tills and review exceptions).